10 Gig access switches: Not just packet pushers anymore
Testing of seven switches turns up major differences in multicast, security, manageability
By DAVID NEWMAN, NETWORK WORLD LAB ALLIANCE
,
Network World
, 03/24/2008
- Share/Email
- Tweet This
- Print
Pity the humble access switch. These packet pushers usually work so well they're stuffed into wiring closets and promptly
forgotten. Packet in, packet out. End of story.
Or is it? If the results of Network World's latest switch tests are any guide, network managers may need a whole new lexicon just to make buying decisions. Our tests
found seven next-generation switches bristle with features that don't exist in many previous models – not just physical features
like 10Gigabit Ethernet uplinks but also 802.1X-based network access control authentication, enhanced multicast support, storm control, denial-of-service protection and IPv6 support.
We assessed switches – all of which sported 48 10/100/1000Mbps ports and two 10G ports -- in 10 areas, encompassing L2 and
L3 IPv4 unicast and multicast performance, L2 multicast group capacity, 802.1X/NAC support, storm control, management and
usability, power consumption, and features.
Review Highlights SlideshowHow we tested these switchesArchive of Network World testsSubscribe to the Network Product Test Results newsletter
Overall, we found big differences in support and stability in products tested from Alcatel-Lucent, Cisco, Dell, D-Link, Extreme, Foundry and HP. For example:
• Multicast throughput and latency varied widely, but more basic issues like group capacity and even system stability were bigger
differentiators in our tests. It took multiple software builds from some vendors just to get through industry-standard multicast tests, and then only using very different group
counts.
• While all switches supported 802.1X authentication, there were major variations in the level of granularity of access control.
Not every switch supported some common use cases, and two switches forwarded unauthenticated traffic when operating in so-called
multi-auth mode, posing security issues.
• All devices had "storm control" features to help mitigate DoS attacks, but these varied widely in terms of rate control and
signature detection.
• IPv6 support remains a work in progress. Some switches fully support IPv6; others can route IPv6 packets but can't be managed
over IPv6; yet others lack support for IPv6 routing protocols.
No one switch excelled in all of the many areas we examined, making it difficult to pick winners across the board. Most switches
do fine on simple forwarding of Ethernet and IPv4 unicast traffic. If that's all that matters to you, pick a switch on price
and usability.
We wouldn't recommend that, though. Increasingly other areas matter more, including security, multicast, and IPv6 – and that's
where real variations among products exist. Cisco's Catalyst 3750E is the most feature-complete device we tested, though the
HP ProCurve 3500yl, Extreme Summit X450 and Foundry FastIron X448 also fared well in most areas.
Because access switches do more than previous-generation products, the first step in picking a product is determining which
features matter most – L2 vs. L3, IPv4 vs. IPv6, unicast vs. multicast, managed vs. unmanaged, on-board security vs. no security
– and then choosing the device that did the best job in these areas (compare more access switches in our Buyer's Guide).
There are plenty of differences among switches, especially when it comes to newer features. Just because basic functions long
ago entered commodity status doesn't mean the switch wars are settled. Far from it; as our test results show, new additions
such as multicast, 802.1X and security are making access switching interesting all over again.
Newman is president of Network Test, an independent test lab in Westlake Village, Calif. He can be reached at dnewman@networktest.com.
Fellow Lab Alliance member Rodney Thayer also contributed to the testing completed for this article.
Thanks
Network World gratefully acknowledges the test equipment vendors that supported this project. Spirent Communications supplied its Spirent
TestCenter Gigabit and 10 Gigabit generator/analyzer, and senior software engineer Timmons C. Player updated Spirent ScriptMaster
for use in multicast testing. Juniper Networks provided Steel-Belted Radius Enterprise Edition 6.1; an IC 6000 network access
server; and Odyssey 802.1X client software for our 802.1X NAC tests. Juniper engineers Denzil Wessels and Christian Macdonald
provided extensive assistance with test bed setup. Thanks too to Fluke Corp., which provided Fluke 322 and 335 clamp meters
for measuring power consumption.

Newman is also a member of the Network World Lab Alliance, a cooperative of the premier reviewers in the network industry
each bringing to bear years of practical experience on every review. For more Lab Alliance information, including what it
takes to become a member, go to www.networkworld.com/alliance.
Partner Content
Simplify Your Branch Infrastructure
Learn how to simplify your branch infrastructure while dramatically increasing app performance with Citrix Branch Repeater.
Download the Free Info Kit
Next-Gen Load Balancing
Free Guide: "Next Gen Load Balancing: 8 Things You Need to Handle Today's Network Traffic" shows you the functionality needed in your next load balancer.
Download the Free Guide
Accelerate Your Web Apps by up to 5x
Free Guide: "The Secret to Getting Maximum Speed from your Web Applications."' Learn how you can deliver Web apps up to 5x faster.
Download the Free Guide
Comments (41)
RE: Review: 10Gig Ethernet access switch shootoutBy Anonymous on March 24, 2008, 11:38 amIt's incredible to me that you gave the top spot to Cisco when it was TWO TIMES the price of the nearest competitor! As a matter of fact you only mention it in passing,...
Reply | Read entire comment
RE: Cisco haterBy Anonymous on March 24, 2008, 6:28 pmGet over it, this was a performance test. I didn't see anything to indicate cost. Bottom line is that you get what you pay for. Based on past experience with many...
Reply | Read entire comment
RE: Cisco haterBy david_newman on March 24, 2008, 6:49 pmHello, I'm the author of this test. I didn't use price as a test criterion for this project because Network World asked me not to. Two issues went into that decision: 1....
Reply | Read entire comment
Force10 GearBy Anonymous on March 25, 2008, 9:14 amI've used about 60% of the switches/routers that you tested as well as Force10 gear. I am wondering why you didn't test their stuff? As I recall some of their...
Reply | Read entire comment
Why no Force10?By Christine Burns on March 25, 2008, 9:35 amForce10, too, declined our invitation to participate, saying it was focusing on other testing projects during our testing window.
Reply | Read entire comment
Switch testingBy Anonymous on March 25, 2008, 4:10 pmAnother "test" rigged to show Cisco winning... I guess the huge number of ads from Cisco on here is a good reason why. Who wants to pay for a switch that starts...
Reply | Read entire comment
View all comments